Lucene search

K
githubGitHub Advisory DatabaseGHSA-MV4H-QM24-X4GH
HistoryMay 14, 2022 - 3:12 a.m.

Converse.js Exposure of Sensitive Information

2022-05-1403:12:35
CWE-200
GitHub Advisory Database
github.com
7
converse.js
inverse.js
vulnerability
sensitive information
exposure
remote attackers
private data

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

53.1%

Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.

Affected configurations

Vulners
Node
conversejsconverse.jsRange<3.3.3
OR
jcbrandconverse.jsRange<3.3.3
VendorProductVersionCPE
conversejsconverse.js*cpe:2.3:a:conversejs:converse.js:*:*:*:*:*:*:*:*
jcbrandconverse.js*cpe:2.3:a:jcbrand:converse.js:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

53.1%

Related for GHSA-MV4H-QM24-X4GH